CVE-2023-46846

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Nov 3, 2023
Updated: Dec 18, 2024
CWE ID 444

Summary

CVE-2023-46846 is a newly disclosed vulnerability affecting the SQUID proxy server. This issue arises due to the server's lenient handling of chunked transfer encoding, enabling a remote attacker to perform HTTP request smuggling. The attacker can inject malicious requests, bypassing security systems like firewalls and frontend proxies, leading to significant security risks. This vulnerability requires careful attention and immediate patching to prevent potential unauthorized access or data manipulation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Squid Software
  • Squid-cache Squid
  • Red Hat Enterprise Linux
  • Redhat Enterprise Linux For Ibm Z Systems

Affected Vendors

  • Red Hat
  • Squid Software Foundation